CVE-2012-1112: Path Traversal
Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selectuserstemplate parameter to index.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-1112?
CVE-2012-1112 is considered a medium severity vulnerability due to its ability to allow remote file inclusion.
How do I fix CVE-2012-1112?
To fix CVE-2012-1112, upgrade Open-Realty CMS to version 2.5.9 or later, which addresses this vulnerability.
What types of systems are affected by CVE-2012-1112?
CVE-2012-1112 affects Open-Realty CMS versions 2.5.8 and earlier, including specific versions like 2.3.1 and 2.3.4.
What kind of attack is possible with CVE-2012-1112?
CVE-2012-1112 allows attackers to perform a directory traversal attack, potentially leading to the execution of arbitrary local files.
Is user data at risk with CVE-2012-1112?
Yes, user data can be at risk with CVE-2012-1112 as it may enable attackers to access sensitive files on the server.